CVE-2026-74644
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/ops-common: putback folios on invalid migrate nid
damon_pa_migrate() and damos_va_migrate() isolate folios into a local list and then call damon_migrate_pages(). When target_nid is invalid (including the scheme default NUMA_NO_NODE / -1), damon_migrate_pages() returns early without putting the folios back to the LRU.
Callers then discard the list head while those folios remain isolated with an extra reference taken by folio_isolate_lru(). The pages stay off the LRU for as long as the mapping exists (anon active+inactive counts drop while RSS does not), and the leftover references can pin the pages after the mapping is gone.
Leer descripción completaMostrar menos
Put the folios back on the invalid-nid path so ignored migration requests still return them to the LRU.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 10
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-74644",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "7c303fa1f311aadc17fa82b7bbf776412adf45de",
"lessThan": "7001c0a1bc9018cd5b2b72ebebb216d738b2ec81",
"versionType": "git"
},
{
"status": "affected",
"version": "7e6c3130690a01076efdf45aa02ba5d5c16849a0",
"lessThan": "460181e4bb47a57776c64f0832c2096de8878cb3",
"versionType": "git"
},
{
"status": "affected",
"version": "7e6c3130690a01076efdf45aa02ba5d5c16849a0",
"lessThan": "cfef454862b7d2776e0955b873dd59af6b47cfcb",
"versionType": "git"
},
{
"status": "affected",
"version": "7e6c3130690a01076efdf45aa02ba5d5c16849a0",
"lessThan": "5deb65c34e682e7c5f5df417a70e223e8fcc5f5a",
"versionType": "git"
},
{
"status": "affected",
"version": "9d0c2d15aff96746f99a7c97221bb8ce5b62db19",
"versionType": "git"
},
{
"status": "affected",
"version": "6.12.44",
"lessThan": "6.12.105",
"versionType": "semver"
},
{
"status": "affected",
"version": "6.16.4",
"lessThan": "6.17",
"versionType": "semver"
}
],
"programFiles": [
"mm/damon/ops-common.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.17"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.17",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.45",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.9",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"mm/damon/ops-common.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-22T16:16:37.730",
"references": [
{
"url": "https://git.kernel.org/stable/c/460181e4bb47a57776c64f0832c2096de8878cb3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5deb65c34e682e7c5f5df417a70e223e8fcc5f5a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7001c0a1bc9018cd5b2b72ebebb216d738b2ec81",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/cfef454862b7d2776e0955b873dd59af6b47cfcb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/ops-common: putback folios on invalid migrate nid\n\ndamon_pa_migrate() and damos_va_migrate() isolate folios into a local list\nand then call damon_migrate_pages(). When target_nid is invalid\n(including the scheme default NUMA_NO_NODE / -1), damon_migrate_pages()\nreturns early without putting the folios back to the LRU.\n\nCallers then discard the list head while those folios remain isolated with\nan extra reference taken by folio_isolate_lru(). The pages stay off the\nLRU for as long as the mapping exists (anon active+inactive counts drop\nwhile RSS does not), and the leftover references can pin the pages after\nthe mapping is gone.\n\nPut the folios back on the invalid-nid path so ignored migration requests\nstill return them to the LRU."
}
],
"lastModified": "2026-08-23T13:16:48.353",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}